Threat Vulnerability Lead
Glocomms
London, UK
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Cyber Security
System Configuration
Python (Programming Language)
Open Web Application Security
Windows PowerShell
Security Information and Event Management
Systems Integration
Software Vulnerability Management
Mitre Att&ck
QRadar
Cyber Threat Analysis
+6 more
Microsoft Sentinel
Cortex XSOAR Platform
Splunk
Qualys
Security Orchestration, Automation & Response
Servicenow
Job description
- Serve as the primary owner and administrator of the organisation’s ThreatConnect Threat Intelligence Platform (TIP), ensuring effective integration, maintenance, and optimisation.
- Develop and maintain ThreatConnect workflows, playbooks, dashboards, and intelligence-sharing processes to improve threat visibility and response capabilities.
- Integrate ThreatConnect with SIEM, SOAR, incident response, and vulnerability management platforms to automate intelligence sharing, enrichment, prioritisation, and reporting.
- Leverage ThreatConnect to manage threat feeds, indicators of compromise (IOCs), threat actor profiles, campaigns, and TTPs aligned to the MITRE ATT&CK framework.
- Continuously improve threat intelligence ingestion, enrichment, correlation, reporting, and operationalisation through ThreatConnect automation and orchestration capabilities.
Requirements
- At least 10 years of experience in cybersecurity engineering or operations roles, with at least 5 years of hands-on experience in Threat Intelligence and Vulnerability Management.
- Strong experience across the threat intelligence lifecycle, including collection, analysis, enrichment, correlation, and dissemination of actionable intelligence.
- Hands-on administration and operational experience with ThreatConnect (or similar Threat Intelligence Platforms), including platform configuration, workflow development, feed management, integrations, and reporting.
- Experience integrating ThreatConnect with SIEM, SOAR, incident response, ticketing, and vulnerability management tools.
- Strong understanding of cyber threat intelligence methodologies, threat actor tracking, IOC management, threat feed ingestion, and intelligence-sharing frameworks.
- Experience working with technologies such as ThreatConnect, Splunk, Microsoft Sentinel, QRadar, ServiceNow, Swimlane, Palo Alto XSOAR, Qualys, Tenable, and Defender TVM.
- Experience automating security workflows using Python, PowerShell, APIs, or similar technologies.
- Strong knowledge of MITRE ATT&CK, NIST CSF, OWASP Top 10, CVEs, and vulnerability risk management best practices.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
6 months ago